Moderate severityNVD Advisory· Published Oct 19, 2010· Updated Apr 29, 2026
CVE-2007-6737
CVE-2007-6737
Description
FTPServer.py in pyftpdlib before 0.2.0 does not increment the attempted_logins count for a USER command that specifies an invalid username, which makes it easier for remote attackers to obtain access via a brute-force attack.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
pyftpdlibPyPI | < 0.2.0 | 0.2.0 |
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- github.com/advisories/GHSA-9x66-ghqx-8g5rghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2007-6737ghsaADVISORY
- code.google.com/p/pyftpdlib/issues/detailnvdWEB
- code.google.com/p/pyftpdlib/source/browse/trunk/HISTORYnvdWEB
- code.google.com/p/pyftpdlib/source/detailnvdWEB
- code.google.com/p/pyftpdlib/source/diffnvdWEB
- github.com/giampaolo/pyftpdlib/issues/20ghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/pyftpdlib/PYSEC-2010-21.yamlghsaWEB
News mentions
0No linked articles in our index yet.